| 12345678910111213141516171819202122232425262728293031 |
- <?php
- namespace App\Http\Middleware;
- use Closure;
- use Illuminate\Http\Request;
- class HstsMiddleware
- {
- /**
- * Handle an incoming request.
- *
- * @param \Illuminate\Http\Request $request
- * @param \Closure(\Illuminate\Http\Request): (\Illuminate\Http\Response|\Illuminate\Http\RedirectResponse) $next
- * @return \Illuminate\Http\Response|\Illuminate\Http\RedirectResponse
- */
- public function handle(Request $request, Closure $next)
- {
- $response = $next($request);
- // Applica l’header HSTS solo se la richiesta è HTTPS
- if ($request->isSecure()) {
- $response->headers->set(
- 'Strict-Transport-Security',
- 'max-age=31536000; includeSubDomains'
- );
- }
- return $response;
- }
- }
|